Getting Data In

Selective routing to UDP without indexing

cafissimo
Communicator

Hello Splunkers, 

Please I would like to know if it is possible, at indexer layer, given a HEC input source, to route some incoming data (of course based on regex) to a UDP destination without indexing that data.

Let's say: sourcetype=hecinput, if it contains word "DEBUG" it should go to UDP destination, all the rest should be indexed as usual.

  • I know that maybe I could use INGEST_EVAL, but I think it supports only _TCP_ROUTING. 

Thanks in advance. 

Tags (3)
0 Karma

cafissimo
Communicator

Addendum:

No solution found yet

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...